Tech & Society

No love lost: Zomato business unaffected by May data breach

India born Zomato announced they reached three million orders in a single month, still going strong months after suffering from a massive data leak in May.

Though a restaurant platform designed to consolidate restaurant reviews and facilitate online ordering didn’t sound like a prime target for a hack, they confirmed the breach on their blog on May 18. Zomato’s customer databases were hacked and the perpetrator accessed emails, names and hashed passwords for 17 million accounts. Though luckily payment information was not compromised.

Reportedly, the company was able to negotiate with the unnamed hacker to prevent misuse of the information, which was going to be sold on a dark web marketplace. The hacker was said to embrace ethical hacking standards and accepted to take down and destroy the data in exchange for Zomato’s sponsorship of a bug bounty program on Hackerone.

The breach involved at least 6.6 million email and password hash combinations. Password hashes are vulnerable to brute-force attacks that can potentially reveal the passwords. When considering that people tend to use the same password across many online services, data breaches can be devastating for affected users.

While Zomato has taken steps to fix the vulnerability that enabled the hacker to access their system, the problem has deeper roots. “Password-secured security solutions have quickly become outdated, leaving millions of businesses vulnerable to breaches”, said Leonardo Cooper, CEO of cyber security company Vault One. As new no-password technologies such as blockchain become the standard, security is expected to increase in both business and private environments.

Nonetheless, Zomato continues to attract attention in the ultra competitive foodtech sector. Since last year it has made great improvement toward profitability as it is getting more visitors and orders, decreasing cash burning, and surviving many other startups—all while staying away from new funding.

Back in May 2016, HSBC Securities & Capital Markets cut Zomato’s valuation by 50% in light of non-profitable operations in all 23 countries it operates in; today, Zomato makes a profit in 11 of them.

Even the most loved startups face setbacks they must overcome, and Zomato is no exception. While the shadow of a data leak remains a dark spot on their history, their sustained deliveries and will to survive show that users will forgive your sins—as long as you have a great product.

 

Daniel Sanchez

Hailing from the Caribbean coast of Colombia, Daniel is a writer and freelance translator with a background in biology. When not word-smithing, you will probably find him chasing frogs somewhere around the tropical belt.

Recent Posts

Delhi Public School students earn MIT-Certified AI credentials, record 50% jump in proficiency

High school students at Delhi Public School (DPS) earned MIT-certified AI credentials and improved their…

3 days ago

Summit AI’s Rural Cyber Blindside: Voice-Cloned Scams Exploding in India’s Digital Heartland

The recent India–AI Impact Summit 2026 demonstrated a defining global inflection point — the transition…

5 days ago

Account Aggregator is emerging as the foundation of India’s open finance architecture

By enabling secure, consent-based financial data sharing, the Account Aggregator framework is laying the groundwork…

6 days ago

ImmuneBridge wants to make cell therapy work for everyone – starting with the factory floor  

There’s a quiet crisis in one of medicine’s most exciting fields. Cell therapy – the…

6 days ago

How AI is Changing Business: Hybrid AI is Coming

Lenovo and NVIDIA are pushing AI into its next phase, scaling real-time, production-ready systems that…

2 weeks ago